Last seven days
- First activity
- Aug 12, 2026
- Last activity
- Aug 12, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
Blackshades is a Windows-focused remote access trojan (RAT) and trojan horse used to remotely control infected computers.
Profile source: Mallory opens in a new tabBlackshades
Blackshades is a Windows-focused remote access trojan (RAT) and trojan horse used to remotely control infected computers. Reported since around 2010, it was sold cheaply on Hack Forums for about US$40 and was described as widely used, including by low-skill operators. U.S. authorities stated it infected more than 500,000 computers worldwide, and reporting cited roughly US$350,000 in sales.
Its documented capabilities include remote unauthorized access, file access and modification, keystroke logging, webcam access, downloading and executing additional files, using the victim system as a proxy, participation in DDoS/TCP flood attacks, and ransomware-style lock-and-ransom behavior. Many antivirus products can detect it, but operators commonly used obfuscation tools sold alongside Blackshades to evade detection.
Documented infection vectors include malicious webpages, including drive-by downloads, and removable media such as USB flash drives. The malware targets Microsoft Windows-based operating systems.
Blackshades appears in multiple threat contexts in the provided content. Citizen Lab and EFF reported its use in 2012 against Syrian opposition forces, and a broader study of attacks in Syria found Blackshades among the predominant malware families used against activists, dissidents, journalists, trade unionists, and NGOs. The content also states that ALUMINUM SARATOGA / Molerats / Operation DustySky used Blackshades among many openly available tools in operations targeting organizations in the Middle East and North Africa. Another source notes a group deploying BlackShades alongside BrowserPasswordDump10, DarkComet, SPARK RAT, and Quasar RAT.
The malware was also used in criminal sextortion activity. In one cited case, Jared James Abrahams pleaded guilty in 2013 to hacking more than 100-150 women and installing Blackshades to obtain nude images and videos; he was sentenced in March 2014. Law-enforcement action against the malware was extensive: in 2014, the FBI coordinated an international crackdown that reportedly resulted in arrests of almost 100 people in 19 countries, 359 searches, and seizure of more than 1,100 electronic devices. Separate reporting states the U.S. Justice Department announced actions against more than 100 people accused of purchasing and using Blackshades. The content attributes Blackshades to Alex Yucel and Michael Hogue, and notes Michael Hogue was arrested and indicted under the Computer Fraud and Abuse Act.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
“ALUMINUM SARATOGA uses many openly available tools for its operations, including… Blackshades…”
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.